PT-2002-1435 · Microsoft · Internet Explorer+1

Published

2002-07-03

·

Updated

2018-10-30

·

CVE-2002-0372

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows Media Player versions 6.4 and 7.1 Media Player for Windows XP
Description The issue allows remote attackers to bypass Internet Explorer's security mechanisms and run code via an executable .wma media file with a license installation requirement stored in the Internet Explorer cache.
Recommendations For Microsoft Windows Media Player versions 6.4 and 7.1, consider disabling the execution of .wma files until a patch is available. For Media Player for Windows XP, restrict access to the executable .wma media files to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0372

Affected Products

Internet Explorer
Windows Media Player